Today's Linux patch cycle delivered Red Hat's largest batch of 2026 with 44 advisories mostly rated Important, plus SUSE sweeping roughly 206 vulnerabilities driven by a 62-CVE Firefox ESR update. Ubuntu's cycle is dominated by kernel and cloud patches carrying privilege-escalation flaws like the Arm TLB and AMD SEV-SNP issues, while Debian's roundcube and Rails fixes rank among the nastiest on paper. A recurring sudo TZ authentication bypass threads through AlmaLinux, Oracle, and Rocky releases, and Fedora's standout item is a proof-assistant update referencing four Rocq logical-integrity CVEs. With severity tied to CVSS scores across nearly every distro, admins can prioritize kernel, browser, and SSH patches before acting on the lower-risk backports.
Red Hat ships 44 advisories as SUSE chases 62 Firefox holes
Today's Linux security roundup pulls in kernel flaws, forged JWT tokens, and a formal proof assistant that shouldn't verify. Debian, Fedora, Ubuntu, Oracle, and everyone else had their turn.
Red Hat has now delivered its largest errata batch of the 2026 cycle so far. Counting the entries, you are looking at 44 advisories, and the overwhelming majority land at the Important band, which is Red Hat's second-highest severity and usually means something is genuinely exploitable.
Kernel is the package to patch first. Half a dozen kernel updates run across the SAP channel, the EUS long-life add-ons, and standard RHEL, so manage any RHEL hosts and that is where your time goes.
Firefox shows up in a different number of ways, with seven advisories each aimed at a distinct RHEL support track. A standard install will not feel most of them, since SAP Solutions, Telecommunications, and EUS make up the bulk, but take a glance to be sure.
There is one detail here worth a wry smile. Three Red Hat Single Sign-On 7.6.13 updates for RHEL 7, 8, and 9 carry the Important title, yet Red Hat rates their actual security impact as none. You get the full errata machinery for what is basically a maintenance release.
A Firefox problem that outnumbers everything else
If numbers are your measure, SUSE is the week's real heavyweight. The company ran a broad security sweep fixing roughly 206 vulnerabilities across 15 announcements, with two items doing nearly all the heavy lifting.
Firefox leads with 62 fixes riding on Mozilla's 153.4.0 ESR build. That covers sandbox escapes, use-after-frees, and JIT problems packed together. CVE-2026-100788 is the one worth a second look: it scores a 9.8 and needs no user input, so a site you visit could reach into your browser without a single click.
Python is the other giant, with 26 fixes centered on archive handling. The tarfile and zipfile modules and any flavor of decompression ride along with the 3.12.14 release.
The lone Critical tag lands on Tomcat and libtcnative. Java apps serving over AJP or WebSocket pick up 15 fixes, including request smuggling and thread-pinning denial-of-service. Each sounds like a misconfiguration until someone actually ships an exploit.
The rest spreads across the SLE 15 live-patch line, the category of fix you are glad does not demand a reboot. Live Patch 30 shows on both SP5 and SP6, but they touch entirely different kernels, so a shared number means nothing. Keep in mind that while you are cataloging installs.
Kernels and cloud builds
Ubuntu's batch is dominated by kernels.
You get the generic kernel plus cloud-flavored builds for GCP, Azure and its secure CVM variant, Oracle, AWS, IBM, GKE, and OEM and NVIDIA Tegra. Several of these are the same update wearing different cloud hats.
CVE-2022-3114, the i.MX clock driver bug that lets a local attacker crash the box, turns up in a lot of them. The GCP and Oracle kernels also pull in CVE-2025-10263, an Arm TLB issue that actually matters because it can escalate privileges or slip past memory protections.
The newest 26.04 kernels carry CVE-2023-20585, an AMD SEV-SNP flaw that could let a hypervisor-level attacker corrupt encrypted guest memory. Run cloud instances and those are the ones to prioritize.
There is one annoying wrinkle too. Those kernel updates arrive with an ABI change, forcing you to recompile and reinstall any third-party modules you built yourself. Budget time for it if you run DKMS-style setups.
Below the kernels sits the grab bag. Tesseract takes the biggest hit with ten CVEs from crafted OCR model files. libsoup draws eight for HTTP/2 and proxy handling. Then the single-issue crowd: Redis, FreeType, FreeRDP, FluidSynth, Go, libwebsockets, GStreamer, RabbitMQ, Unbound, and Ubuntu Pro for WSL, which was leaking its attach token in command-line arguments, a rather conspicuous slip.
The long tail of distro patches
Debian's round is nastier than its severity badges suggest. The roundcube advisory carries no CVE yet, but bundles a grab bag of webmail trouble: cross-site scripting, a CSRF bypass, email header injection, CSS property injection, and privilege escalation. That is a lot of ways to turn someone else's inbox into someone else's mess.
Rails got the crowded treatment with ten CVEs spanning XSS, denial-of-service, path traversal, and arbitrary code execution. If you run any Rails app and have not updated, this is the longest list you will find today. The bookworm backports also close two puma PROXY protocol headaches and a suricata-update path traversal that lets malformed rules overwrite files on disk.
AlmaLinux spread its updates across releases 8, 9, and 10. The kernels are the big ones by volume, with version 8 taking two near-identical releases, one regular and one real-time, each patching 29 issues, though most are the usual memory-corruption and race-condition bugs across network drivers, KVM, and storage.
The sudo fix deserves a second look. Setting the TZ environment variable let a user slip past time-based authorization, so the NOTBEFORE and NOTAFTER constraints could be bypassed entirely, and it rolled out across all three releases.
That same sudo TZ bypass reappears in the Oracle and Rocky batches this week, and the CVE keeps traveling. The vim patch is worth double-checking as well, since a crafted tags file could trigger arbitrary command execution. Oracle specifically has the gnutls updates that mark ML-KEM as FIPS-unapproved on both OL9 and OL10, which only bites if compliance tooling is poking at your crypto policies.
Fedora leaned into the mundane-but-necessary side of security this week. Fourteen of the Fedora 44 updates cluster around a single advisory, all from a fresh 9.3.0 release of rocq, the formal proof assistant that split off as a maintained fork of Coq. The advisory carries a security flag because it references four Rocq logical-integrity issues, including two 2026 CVEs that let you manufacture proofs that should not verify. Hand Rocq a proof and actually trust the result, and that is the one to watch. Everyone else just got a rebuild.
The standalone fixes are more conventional. httpd jumps to 2.4.69 with six CVEs including a CGI redirect flaw that allows arbitrary code execution. Python 3.14.8 carries seven security fixes, though only one, a use-after-free in SSLContext, gets spelled out. Install those two first if I were you.
Rocky cleared its repos with 26 advisories across releases 8, 9, and 10. Twenty-five sit at Important, with a single Moderate wedged in at ghostscript on release 8. bind, sudo, freerdp, vim, and mariadb-connector-c repeat across releases, and every advisory ties its severity to a specific CVSS score, so you can grade the risk before patching instead of blasting everything at once.
Slackware kept it simple with an openssh update on both 15.0 and -current. The package ships in two flavors per release, each with an MD5 checksum for verification. Simple enough.
A Breakdown of the Updates
AlmaLinux
AlmaLinux pushed a batch of security updates on October 6 across its current and aging releases (versions 8, 9, and 10). Almost every advisory tops out at "Important" severity, and a handful are worth your attention because they open real doors rather than just tidy up housekeeping.
The kernel updates are the big ones by volume. AlmaLinux 8 received two near-identical kernel releases, one regular and one real-time variant, each patching 29 issues. That is a lot of CVE identifiers for a single update, though most of them are the usual memory-corruption and race-condition bugs spread across network drivers, KVM virtualization, and storage paths. If you run either kernel, this lands on your machine.
A few smaller updates deserve a second look. The sudo fix (CVE-2026-96512) covers something quietly useful: setting the TZ environment variable let a user slip past time-based authorization, so the NOTBEFORE and NOTAFTER constraints could be bypassed entirely. It rolled out across all three OS releases. The BIND update for version 10 bundles five denial-of-service holes, mostly around SVCB/HTTPS handling and DNSSEC, while the vim patch (CVE-2026-73073) is the sort that makes you double-check your own config files, since a crafted tags file could trigger arbitrary command execution.
Beyond the headline items sits a grab bag of library fixes. libpcap closed an out-of-bounds read and write that allowed arbitrary memory access, gd patched a GIF buffer overflow, and MariaDB squashed an SQL injection tied to improper big5 character set handling. librabbitmq and GIMP picked up heap overflows, with the image editor absorbing four separate bugs. Node.js gathered two DoS issues, and Ruby 2.5 saw its DNS resolver and MongoDB driver patched.
| Advisory ID | Package | Version | Severity | CVEs |
|---|---|---|---|---|
| ALSA-2026:75746 | kernel-rt | 8 | Important | 29 |
| ALSA-2026:75747 | kernel | 8 | Important | 29 |
| ALSA-2026:75680 | gd | 8 | Important | 1 |
| ALSA-2026:75674 | mariadb-connector-c | 8 | Important | 1 |
| ALSA-2026:75580 | sudo | 8 | Important | 1 |
| ALSA-2026:75582 | librabbitmq | 8 | Important | 1 |
| ALSA-2026:76045 | libpcap | 8 | Important | 1 |
| ALSA-2026:73519 | ruby:2.5 | 8 | Important | 2 |
| ALSA-2026:75673 | mariadb-connector-c | 9 | Important | 1 |
| ALSA-2026:75571 | sudo | 9 | Important | 1 |
| ALSA-2026:75575 | gimp | 9 | Important | 4 |
| ALSA-2026:74438 | kernel | 9 | Moderate | 3 |
| ALSA-2026:75579 | sudo | 10 | Important | 1 |
| ALSA-2026:75769 | vim | 10 | Important | 1 |
| ALSA-2026:75577 | bind | 10 | Important | 5 |
| ALSA-2026:75864 | nodejs22 | 10 | Important | 2 |
| ALSA-2026:75581 | mod_auth_openidc | 10 | Important | 1 |
Debian GNU/Linux
Debian shipped a batch of security patches this week, and a few of them deserve your attention before something less pleasant does. Most of the fixes land in trixie (the current stable release), while two are LTS backports for the older bookworm.
The roundcube advisory is the nastiest on paper: no CVE number yet, but a grab bag of webmail trouble including cross-site scripting, a CSRF bypass, email header injection, CSS property injection, and privilege escalation. That's a lot of ways to turn someone else's inbox into someone else's mess. It's patched in 1.6.19+dfsg-0+deb13u1.
Rails got the crowded treatment, with ten CVEs spanning XSS, denial-of-service, path traversal, and arbitrary code execution. If you run any Rails app and haven't updated, this is the longest list here. ruby-jwt missed on HMAC validation for some tokens, which is the exact gap that makes a forged token look legitimate, and node-shell-quote closes a denial-of-service and a shell injection hole. All three trixie fixes are already out.
On the LTS side, puma has two PROXY protocol headaches: one lets an attacker keep sending bytes without CRLF to pin down memory and CPU, and the other lets someone spoof the source IP by replaying a PROXY header over a kept-alive connection. suricata-update takes a path traversal that lets malformed rules overwrite files on disk. Both backports are for bookworm.
Upgrading through your normal update path covers all of it.
| Package | CVE(s) | What it does | Fixed in | Branch |
|---|---|---|---|---|
| roundcube | none assigned yet | XSS, CSRF bypass, header injection, CSS injection, remote content bypass, info disclosure, privilege escalation | 1.6.19+dfsg-0+deb13u1 | trixie (stable) |
| rails | CVE-2026-33168, 33169, 33170, 33173, 33174, 33176, 33195, 33202, 33658, 66066 | XSS, DoS, path traversal, arbitrary code execution | 2:7.2.2.2+dfsg-2~deb13u2 | trixie (stable) |
| node-shell-quote | CVE-2026-13311, CVE-2026-102422 | Denial-of-service, shell command injection | 1.7.4+~1.7.1-1+deb13u2 | trixie (stable) |
| ruby-jwt | CVE-2026-45363 | Insufficient HMAC validation lets forged tokens through | 2.7.1-1+deb13u1 | trixie (stable) |
| puma | CVE-2026-47736, CVE-2026-47737 | Memory/CPU exhaustion and source IP spoofing via PROXY protocol v1 | 5.6.5-3+deb12u2 | bookworm (LTS) |
| suricata-update | CVE-2026-63347 | Path traversal lets malformed rules overwrite files | 1.2.7-1+deb12u1 | bookworm (LTS) |
Fedora Linux
Fedora's push this week leans hard into the mundane-but-necessary side of security updates rather than any headline CVE. Fedora 44 picked up a wide pile of packages, with a few items following along on 43.
Fourteen of the Fedora 44 updates cluster around a single advisory, all kicked off by the same root cause: a fresh 9.3.0 release of rocq, the formal proof assistant that split off as a maintained fork of Coq. Why3, zenon, flocq, and gappalib-coq were simply rebuilt against it, while rocq itself and its standard library got the actual version bumps. The advisory is flagged security because it references four Rocq logical-integrity issues, including two CVEs from 2026 that let you manufacture proofs that should not verify. If you ever hand Rocq a proof and actually trust the result, that's the one worth paying attention to; everyone else just gets a rebuild.
The standalone security patches are more conventional. httpd jumps to 2.4.69 and bundles six distinct CVEs spanning use-after-free bugs in mod_ldap and mod_http2, a denial of service in mod_proxy_ftp, a CGI redirect flaw that allows arbitrary code execution, a shared-lock DoS, and session cookie leakage during internal redirects. Python 3.14.8 carries seven security fixes, though only one (a use-after-free in SSLContext) gets spelled out in the tracker. Those two are the ones I'd install first if I were you.
Below those, the rest are mostly single-issue hardening. tesseract and libical each absorb backported buffer-overflow and DoS fixes, cockpit caps concurrent connections and sanitizes URLs, musescore patches a FluidSynth heap overflow triggered by a MIDI setting, janus lands a security release that quietly fixes memory leaks and a couple of plugin bypasses, and golang-x-mod gets rebuilt to absorb a batch of Go standard-library holes. Freerdp and the accompanying python3-docs round out the batch without touching a vulnerability.
Three of these (janus, golang-x-mod, tesseract) also shipped for Fedora 43, since 43 is in maintenance mode and takes only security backports rather than fresh feature versions.
| Package | Fedora | Version | What changed | The catch |
|---|---|---|---|---|
| why3 | 44 | 1.8.2-11 | Rebuilt for rocq 9.3.0 | Pure rebuild; advisory flags four Rocq logical-integrity CVEs |
| rocq-stdlib | 44 | 9.2.0-1 | Up to 9.2.0, now uses dune buildsystem | Standard library for the Rocq prover |
| zenon | 44 | 0.8.5-41 | Rebuilt for rocq 9.3.0 | Automated theorem prover, rebuild only |
| rocq | 44 | 9.3.0-1 | Up to 9.3.0, fix rocq.xml | Core prover; advisory covers 4 CVEs |
| gappalib-coq | 44 | 1.11.0-1 | Up to 1.11.0, rocq 9.3.0 compat patch | Coq support for the Gappa prover |
| flocq | 44 | 4.2.2-3 | Rebuilt for rocq 9.3.0 | Float formalization, rebuild only |
| httpd | 44 | 2.4.69-1 | Up to 2.4.69 | 6 CVEs (2 after-free, DoS x3, CGI RCE, cookie leak) |
| python3.14 | 44 | 3.14.8-1 | Up to 3.14.8 | 7 security fixes (SSLContext UAF only one detailed) |
| python3-docs | 44 | 3.14.8-1 | Docs for 3.14.8 | Companion docs, no vuln fix |
| freerdp | 44 | 3.32.1-1 | Up to 3.32.1 | Bugfix release, no vuln fix |
| janus | 44 | 1.4.2-1 | Up to 1.4.2 security release | Memory leaks, plugin bypasses, thread caps |
| musescore | 44 | 4.7.5-3 | Patch CVE-2026-61714 | FluidSynth heap overflow via MIDI config |
| golang-x-mod | 44 | 0.28.0-5 | Rebuilt for security fixes | 4 Go stdlib CVEs (tls, pem, asn1, x509) |
| libical | 44 | 3.0.20-8 | Patch CVE-2026-88383 | DoS via crafted iCalendar property |
| cockpit | 44 | 368-1 | Limit connections, sanitize URLs | 3 CVEs (DoS, trailing slash, PackageKit) |
| tesseract | 44 | 5.5.3-2 | Backport CVE-2026-88047 to 88054 | 8 buffer-overflow fixes |
| janus | 43 | 1.4.2-1 | Security release | Same hardening as F44 |
| golang-x-mod | 43 | 0.27.0-4 | Rebuilt for security fixes | Same Go stdlib CVEs (0.27.0 build) |
| tesseract | 43 | 5.5.3-2 | Backport CVE-2026-88047 to 88054 | Same 8 overflow fixes |
Oracle Linux
Oracle Linux has pushed another round of errata, and this batch stretches from the aging OL7 all the way up to the relatively new OL10. It's a grab bag of "Important" security advisories mixed with ordinary bug-fix-and-enhancement updates, so you get to pick whichever applies to your stack.
Two security rollups carry the most baggage. The vim update for OL9 and the kernel update for OL8 each bring a long tail of CVEs, the latter running to nearly three dozen. A handful of vulnerabilities show up more than once: the sudo TZ environment variable authentication bypass (CVE-2026-96512) landed on OL8, OL9, and OL10, while mariadb-connector-c's flaw (CVE-2026-44172) got patched on both OL8 and OL9.
The gnutls updates are about as nerve-wracking as it gets. Both the OL9 and OL10 releases just mark ML-KEM as FIPS-unapproved. Nothing to panic about unless you have compliance tooling poking at crypto policies. The nodejs22 advisory for OL10 is another bit of a puzzle, it names two CVEs but the only change listed is adding c-ares as a dependency, which suggests the real fix arrived in an earlier bump.
On the bug-fix side, a few of these are quietly useful. The OL7 iscsi-initiator-utils patch repairs a hypervisor that wouldn't boot over iSCSI due to truncation, which is exactly the sort of problem that ruins your weekend. The oVirt vdsm updates run the same VM-cloning fix on OL8 and OL9, and the ovirt-engine refresh just re-reads storage-pool metadata after a master-role switch.
| Advisory | OS | Package | Type | What it actually does |
|---|---|---|---|---|
| ELBA-2026-500369 | OL8 | vdsm (36 packages) | Bug fix | Fixes VM cloning problem on OL9 |
| ELBA-2026-500368 | OL8 | ovirt-engine-appliance | Bug fix | Adds an OL9 appliance (release note is delightfully garbled) |
| ELBA-2026-500366 | OL8 | ovirt-engine | Bug fix | Refreshes storage-pool metadata on every UP host after a master-role switch |
| ELSA-2026-75673 | OL9 | mariadb-connector-c | Security | CVE-2026-44172 fix |
| ELSA-2026-75768 | OL9 | vim | Security | CVEs for command injection, buffer overflows, and code execution across omni-completion, netrw, terminal emulator, and more |
| ELSA-2026-75571 | OL9 | sudo | Security | CVE-2026-96512 (TZ env var bypasses NOTBEFORE/NOTAFTER auth) |
| ELBA-2026-76028 | OL9 | gnutls | Bug fix/enhancement | Marks ML-KEM FIPS-unapproved |
| ELBA-2026-500371 | OL9 | keepalived | Bug fix | Stops restoring file timestamps while inspecting scripts |
| ELSA-2026-76045 | OL8 | libpcap | Security | CVE-2026-0799, adding bounds checks for BPF scratch memory register indices |
| ELSA-2026-75747 | OL8 | kernel | Security/Bug/enhancement | 28 CVEs plus driver signing and certificate updates |
| ELSA-2026-75580 | OL8 | sudo | Security | CVE-2026-96512 plus a long backlist of prior sudo fixes |
| ELSA-2026-75674 | OL8 | mariadb-connector-c | Security | CVE-2026-44172 fix |
| ELBA-2026-500365 | OL7 | iscsi-initiator-utils | Bug fix | Fixes hypervisor failing to boot over iSCSI due to truncation |
| ELSA-2026-75864 | OL10 | nodejs22 | Security | CVE-2026-9496 and CVE-2026-19534 (only real change: adds c-ares dependency) |
| ELSA-2026-75579 | OL10 | sudo | Security | CVE-2026-96512 plus execveat and privilege-drop fixes |
| ELBA-2026-76027 | OL10 | gnutls | Bug fix/enhancement | Marks ML-KEM FIPS-unapproved |
| ELBA-2026-500370 | OL9 | vdsm (36 packages) | Bug fix | Fixes VM cloning problem |
| ELBA-2026-500367 | OL9 | ovirt-engine | Bug fix | Refreshes storage-pool metadata after a master-role switch |
| ELSA-2026-75570 | OL10 | freerdp | Security | 11 CVEs backported across Remote Desktop handling |
Red Hat Enterprise Linux
Red Hat has pushed another round of security errata, and the 2026 batch is a sizable one. Counting the list, you are looking at 44 advisories, and the vast majority land at the Important rating. That is Red Hat's second-highest band, which usually means there is something exploitable worth patching.
Firefox turns up more often than anything else, with seven separate advisories each aimed at a different RHEL channel or support track. If you run a standard RHEL install, most of these specialty variants (SAP Solutions, Telecommunications, EUS) will not touch you, but it is worth a glance to confirm.
Kernel is the other heavy hitter. Half a dozen kernel updates span everything from the SAP channel to the long-life EUS add-ons. If you manage RHEL hosts, kernel is the package to patch first.
Two things stand out in the pile. First, three Red Hat Single Sign-On 7.6.13 updates for RHEL 7, 8, and 9 carry the Important title while Red Hat rates their actual security impact as none. You get the full errata machinery for what amounts to a maintenance release. Second, the only three Moderate advisories this round are firewalld, glibc, and ghostscript, the kind of lower-risk fixes you can slot into the next routine window rather than the next maintenance action.
OpenShift gets its share as well. Releases 4.22.17, 4.21.36, 4.20.41, and 4.19.50 arrive alongside a MicroShift 4.21.36. If you orchestrate containers on RHEL, that cluster-wide work is where your attention should go.
| RHSA ID | Product | Severity | RHEL Channel / Notes |
|---|---|---|---|
| RHSA-2026:76637 | Apicurio Registry (container images) 3.3.3 GA | Important | Container Catalog |
| RHSA-2026:75768 | vim | Important | RHEL 9 |
| RHSA-2026:76733 | rust-rpm-sequoia | Important | RHEL 9 |
| RHSA-2026:76734 | rust-rpm-sequoia | Important | RHEL 10 |
| RHSA-2026:76735 | rust-sequoia-sqv | Important | RHEL 10 |
| RHSA-2026:76740 | firefox | Important | RHEL 9.4 SAP Solutions |
| RHSA-2026:76741 | firefox | Important | RHEL 7 Extended Lifecycle Support |
| RHSA-2026:76742 | firefox | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:76743 | opentelemetry-collector | Important | RHEL 10 |
| RHSA-2026:76745 | firefox | Important | RHEL 8.6 AMCUSS + EUS Long-Life |
| RHSA-2026:76746 | firefox | Important | RHEL 8.8 SAP + Telecommunications |
| RHSA-2026:76747 | freerdp | Important | RHEL 8 |
| RHSA-2026:76748 | openssh | Important | RHEL 10.0 EUS |
| RHSA-2026:76762 | perl-DBI | Important | RHEL 10 |
| RHSA-2026:76763 | dovecot | Important | RHEL 8 |
| RHSA-2026:76777 | glibc | Moderate | RHEL 8 |
| RHSA-2026:76795 | grafana | Important | RHEL 9.4 SAP Solutions |
| RHSA-2026:76809 | grafana | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:76844 | firewalld | Moderate | RHEL 9.6 EUS |
| RHSA-2026:76877 | ghostscript | Moderate | RHEL 8 |
| RHSA-2026:76894 | firefox | Important | RHEL 8.4 AMCUSS + EUS Long-Life |
| RHSA-2026:76895 | firefox | Important | RHEL 9.6 EUS |
| RHSA-2026:76945 | python3.9 | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:76993 | openssh | Important | RHEL 9.4 SAP Solutions |
| RHSA-2026:77028 | python3.12 | Important | RHEL 8 |
| RHSA-2026:77214 | kernel-rt | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:77215 | kernel | Important | RHEL 9.2 SAP Solutions |
| RHSA-2026:77216 | kernel | Important | RHEL 8.6 AMCUSS + EUS Long-Life |
| RHSA-2026:77217 | kernel | Important | RHEL 8.4 AMCUSS + EUS Long-Life |
| RHSA-2026:77218 | kernel | Important | RHEL 9.4 SAP Solutions |
| RHSA-2026:77301 | kernel | Important | RHEL 8.8 SAP + Telecommunications |
| RHSA-2026:77370 | mod_auth_openidc:2.3 | Important | RHEL 8.8 SAP + Telecommunications |
| RHSA-2026:77371 | mod_auth_openidc:2.3 | Important | RHEL 8.6 AMCUSS + EUS |
| RHSA-2026:77372 | mod_auth_openidc:2.3 | Important | RHEL 8.4 AMCUSS + EUS Long-Life |
| RHSA-2026:74376 | OpenShift Container Platform 4.20.41 | Important | OpenShift |
| RHSA-2026:74377 | OpenShift Container Platform 4.20.41 | Important | OpenShift |
| RHSA-2026:74379 | OpenShift Container Platform 4.21.36 | Important | OpenShift |
| RHSA-2026:74427 | OpenShift Container Platform 4.22.17 | Important | OpenShift |
| RHSA-2026:74428 | OpenShift Container Platform 4.22.17 | Important | OpenShift |
| RHSA-2026:74433 | OpenShift Container Platform 4.19.50 | Important | OpenShift |
| RHSA-2026:74796 | MicroShift 4.21.36 | Important | OpenShift (MicroShift) |
| RHSA-2026:76128 | Red Hat Single Sign-On 7.6.13 | None | RHEL 7 |
| RHSA-2026:76129 | Red Hat Single Sign-On 7.6.13 | None | RHEL 8 |
| RHSA-2026:76130 | Red Hat Single Sign-On 7.6.13 | None | RHEL 9 |
Rocky Linux
Rocky Linux just cleared out its repos with a batch of errata, and the gist is that you've got a pile of security updates sitting there. Across three releases (8, 9, and 10), that's 26 advisories, 25 flagged Important and one wedged at Moderate.
The kernel updates are usually the ones that draw the most attention, and they're spread the way you'd expect. Rocky Linux 8 got both a regular kernel and a real-time build, while the newer 10.0 picked up a fresh kernel too. If your 8 boxes run real-time workloads, kernel-rt is the one to grab.
bind, sudo, freerdp, vim, and mariadb-connector-c are the repeat offenders, showing up in two or three releases each. Not exactly a shocker, given how often those packages turn up in vulnerability reports. The rest are mostly single calls: gd, librabbitmq, libvirt, mod_auth_openidc, nodejs (both the module stream on 8 and the 10.0 package), libpcap, dovecot, and rust-rpm-sequoia. The pki-core:10.6 update on 8 drags along a whole cluster of related modules, so that one covers more ground than the name suggests.
The only Moderate severity is ghostscript on release 8, which means it can wait behind the Important entries if you're triaging. Every advisory ties its severity to a specific CVSS base score tied to individual CVEs, so you can grade the risk before you patch rather than just applying everything at once.
| RLSA ID | Package(s) | Release | Severity |
|---|---|---|---|
| RSA-2026:75767 | bind | Linux 9 | Important |
| RSA-2026:75571 | sudo | Linux 9 | Important |
| RSA-2026:75578 | bind9.18 | Linux 9 | Important |
| RSA-2026:75673 | mariadb-connector-c | Linux 9 | Important |
| RSA-2026:76733 | rust-rpm-sequoia | Linux 9 | Important |
| RSA-2026:75768 | vim | Linux 9 | Important |
| RSA-2026:75746 | kernel-rt | Linux 8 | Important |
| RSA-2026:75674 | mariadb-connector-c | Linux 8 | Important |
| RSA-2026:75680 | gd | Linux 8 | Important |
| RSA-2026:75582 | librabbitmq | Linux 8 | Important |
| RSA-2026:75747 | kernel | Linux 8 | Important |
| RSA-2026:75580 | sudo | Linux 8 | Important |
| RSA-2026:75870 | nodejs:22 | Linux 8 | Important |
| RSA-2026:75573 | pki-core:10.6 (tomcatjss, resteasy, ldapjdk, jss, plus module variants) | Linux 8 | Important |
| RSA-2026:76763 | dovecot | Linux 8 | Important |
| RSA-2026:76877 | ghostscript | Linux 8 | Moderate |
| RSA-2026:76747 | freerdp | Linux 8 | Important |
| RSA-2026:76045 | libpcap | Linux 8 | Important |
| RSA-2026:75570 | freerdp | Linux 10 | Important |
| RSA-2026:75577 | bind | Linux 10 | Important |
| RSA-2026:75583 | libvirt | Linux 10 | Important |
| RSA-2026:75769 | vim | Linux 10 | Important |
| RSA-2026:75581 | mod_auth_openidc | Linux 10 | Important |
| RSA-2026:75579 | sudo | Linux 10 | Important |
| RSA-2026:75576 | kernel | Linux 10 | Important |
| RSA-2026:75864 | nodejs22 | Linux 10 | Important |
Slackware Linux
Slackware pushed an openssh update out this time around, and it's the kind of security patch you want to apply without much fuss. openssh 10.6p1 (advisory SSA:2026-279-01) lands on both Slackware 15.0 and -current to close out some security holes. SSH is about as important as any service you're running, so this one earns the priority rather than sitting at the bottom of a queue.
The packages come in two flavors per release. Slackware 15.0 gets i586 and x86_64 builds, while -current ships i686 and x86_64 (the newer baseline, as you'd expect). Each has an MD5 checksum so you can verify the download before installing. The upgrade path is the usual Slackware dance: run upgradepkg as root against the matching .txz, then restart sshd with the rc script. It's a small update, but it's the thing you're relying on to keep the doors to your boxes open.
| Version | Advisory | MD5 (i386) | MD5 (x86_64) | Action |
|---|---|---|---|---|
| openssh-10.6p1 | SSA:2026-279-01 | 5b260bc4e7cebdc5cc4f6baf8d01e2b8 (15.0) / ccd016b5c4c2be7bad2637a5bc9c6386 (-current) | 00207779419c3a4a10b95e900dd226b6 (15.0) / ede230efe189fda322fd4da20bef7ae0 (-current) | upgradepkg, then restart sshd |
SUSE Linux
SUSE put out a sizeable security sweep, and the short version is: if any of the 15 versions below are on your systems, schedule some patching. The day's two biggest items landed in Firefox and Python, 62 and 26 fixed vulnerabilities respectively, out of roughly 206 across the whole batch. The rest is Linux kernel live patches, which is the category of fix you're glad doesn't need a reboot.
Firefox is the one that genuinely wants your attention. Mozilla's 153.4.0 ESR build closes a broad set of holes, several sandbox escapes, use-after-frees, and JIT problems thrown together. CVE-2026-100788 deserves a look on its own merits: it's a 9.8 and takes no user input, meaning a site you visit could reach you without a single click.
Python 3.12's haul centers on archive handling, tarfile, zipfile, decompression of any kind. The update rides along with the 3.12.14 release, so security and routine bug fixes arrive together.
The kernel patches spread across SLE 15 SP4 through SP7, with SP4 ending up with three of them (57, 58, plus the earlier 30). SP5 and SP6 both carry a "Live Patch 30," but they patch entirely different kernels, so the shared number means nothing. Everything reads "important" on SUSE's scale, just below critical.
The only critical tag goes to the Tomcat and libtcnative bundle. Java apps serving over AJP or WebSocket get 15 fixes here, covering request smuggling and thread-pinning denial of service. Both sound like misconfiguration until someone shows you the exploit.
The remainder of the Tumbleweed announcements are smaller fry: valkey, a few Python packages, and jupyterlab. Most carry a single CVE, though Werkzeug picked up six. Chromium closed 11 holes for openSUSE Backports on SP7.
| Announcement | What it updates | CVEs fixed | Severity | Notes |
|---|---|---|---|---|
| SUSE-SU-2026:4545-1 | MozillaFirefox | 62 | Important | Firefox ESR 153.4.0 |
| SUSE-SU-2026:4534-1 | python312 | 26 | Important | Rides 3.12.14 |
| SUSE-SU-2026:4518-1 | Linux kernel (Live Patch 4) | 19 | Important | SLE 15 SP6 + SP7, kernel 6.4 |
| SUSE-SU-2026:4544-1 | libtcnative-1-0 / tomcat11 | 15 | Critical | Tomcat 11.0.26, libtcnative 1.3.9 |
| SUSE-SU-2026:4519-1 | Linux kernel (Live Patch 33) | 13 | Important | SLE 15 SP4 + SP5, kernel 5.14 |
| SUSE-SU-2026:4516-1 | Linux kernel (Live Patch 30) | 13 | Important | SLE 15 SP5, kernel 5.14 |
| SUSE-SU-2026:4530-1 | Linux kernel (Live Patch 57) | 12 | Important | SLE 15 SP4, kernel 5.14 |
| SUSE-SU-2026:4540-1 | Linux kernel (Live Patch 30) | 11 | Important | SLE 15 SP6, kernel 6.4 |
| openSUSE-SU-2026:0345-1 | chromium | 11 | Important | Chromium 154.0.8037.97, Backports SP7 |
| SUSE-SU-2026:4531-1 | Linux kernel (Live Patch 58) | 7 | Important | SLE 15 SP4, kernel 5.14 |
| openSUSE-SU-2026:11943-1 | python313-Werkzeug | 6 | Moderate | 6 CVEs |
| openSUSE-SU-2026:11949-1 | python310 | 4 | Moderate | 3.10.21, Tumbleweed |
| openSUSE-SU-2026:11945-1 | jupyter-jupyterlab | 3 | Moderate | 4.5.11, Tumbleweed |
| openSUSE-SU-2026:11951-1 | valkey | 1 | Moderate | 9.1.2, Tumbleweed |
| openSUSE-SU-2026:11946-1 | python313-langchain-anthropic | 1 | Moderate | 1.7.5, Tumbleweed |
| openSUSE-SU-2026:11944-1 | python313-azure-storage-queue | 1 | Moderate | 12.18.0, Tumbleweed |
| openSUSE-SU-2026:11947-1 | python313-sglang | 1 | Moderate | 0.5.20, Tumbleweed |
Ubuntu Linux
Ubuntu rolled out another batch of security patches. This roundup is a mixed lot. The kernel updates carry the most substance, while the application fixes range from the mildly annoying to the genuinely worth a reboot.
The kernels eat up most of the space. You get the generic kernel plus cloud-flavored builds for GCP, Azure (and its secure CVM variant), Oracle, AWS, IBM, GKE, along with OEM and NVIDIA Tegra. Several of these are the same update wearing different cloud hats, and a couple of notices stack multiple CVEs. CVE-2022-3114, the i.MX clock driver bug that lets a local attacker crash the machine, shows up in a lot of them. GCP and Oracle kernels also pull in CVE-2025-10263, an Arm TLB issue that is actually worth your time because it can escalate privileges or slip past memory protections. The newer 26.04 kernels carry CVE-2023-20585, an AMD SEV-SNP flaw that could let a hypervisor-level attacker corrupt encrypted guest memory. If you run cloud instances, those are the ones to prioritize. And watch out for the ABI change attached to the kernel updates, since it forces you to recompile and reinstall any third-party modules you built yourself.
The application fixes are the grab bag below. Tesseract takes the biggest hit with ten CVEs, mostly about crafted OCR model files leading to code execution. libsoup pulls in eight, mostly HTTP/2 and proxy handling. U-Boot picks up four for its ZFS, ext4, and IP defragmentation handling. Then there's the single-issue crowd: sg3-utils running commands as root, Redis, FreeType, FreeRDP, FluidSynth, Go, libwebsockets, GStreamer, RabbitMQ, Unbound, and Ubuntu Pro for WSL, which was leaking its attach token in command-line arguments, a rather conspicuous mistake. A few notices, like FreeRDP and the NVIDIA Tegra kernel, don't list a CVE at all.
| USN | Software | Vulnerability | CVE(s) | Affected releases | Action |
|---|---|---|---|---|---|
| USN-8873-1 | Unbound | Memory mishandling, DoS or code execution | CVE-2026-81642, CVE-2026-82717 | 7 LTS releases (14.04 through 26.04) | Update unbound, libunbound8, python3-unbound |
| USN-8878-1 | linux-gcp-5.15 (GCP kernel) | i.MX clock null deref; Arm TLB priv-esc | CVE-2022-3114, CVE-2025-10263 | Ubuntu 20.04 LTS | Update linux-image-gcp-5.15; reboot |
| USN-8877-1 | linux-gcp / linux-gcp-fips (5.15) | i.MX clock null deref | CVE-2022-3114 | Ubuntu 22.04 LTS | Update; reboot |
| USN-8876-1 | linux-azure-fde (Azure CVM kernel) | i.MX clock null deref | CVE-2022-3114 | Ubuntu 22.04 LTS | Update; reboot |
| USN-8879-1 | linux-oracle-5.15 | i.MX clock null deref; Arm TLB priv-esc | CVE-2022-3114, CVE-2025-10263 | Ubuntu 20.04 LTS | Update; reboot |
| USN-8875-1 | linux (generic + many cloud variants) | i.MX clock null deref (plus broad kernel fixes) | CVE-2022-3114 | Ubuntu 22.04, 20.04 LTS | Update; reboot |
| USN-8869-1 | RabbitMQ Server | HTTP/2 header handling exhausts memory | CVE-2026-59248 | 4 LTS releases (20.04 through 26.04) | Update; restart RabbitMQ |
| USN-8881-1 | FreeType | CID font loader leads to DoS | CVE-2026-95512 | 3 LTS releases (22.04 through 26.04) | Update libfreetype6 |
| USN-8880-1 | FreeRDP (freerdp3) | Multiple issues: info leak, crash, code execution | (no CVE listed) | Ubuntu 26.04, 24.04 LTS | Update freerdp3 |
| USN-8874-1 | sg3-utils | Improper device ID sanitizing runs commands as admin | CVE-2026-16313 | 7 LTS releases (14.04 through 26.04) | Update sg3-utils |
| USN-8882-1 | Tesseract | 10 CVEs from crafted .traineddata files; DoS or code execution | CVE-2026-73066 through CVE-2026-88054 | 7 LTS releases (14.04 through 26.04) | Update libtesseract* |
| USN-8887-1 | linux (7.0 + cloud variants) | AMD SEV-SNP RMP check flaw (encrypted guest memory) | CVE-2023-20585 | Ubuntu 26.04 LTS | Update; reboot |
| USN-8886-1 | linux-nvidia-tegra (5.15) | Multiple kernel issues | (no CVE listed) | Ubuntu 24.04 LTS | Update; reboot |
| USN-8889-1 | linux-oem-7.0 | AMD SEV-SNP RMP check flaw | CVE-2023-20585 | Ubuntu 26.04 LTS | Update; reboot |
| USN-8888-1 | linux-azure / linux-azure-fde (7.0) | AMD SEV-SNP RMP check flaw | CVE-2023-20585 | Ubuntu 26.04 LTS | Update; reboot |
| USN-8885-1 | FluidSynth | pitch_bend_range + MIDI channel heap overflow | CVE-2026-58264, CVE-2026-61714 | 7 LTS releases (14.04 through 26.04) | Update fluidsynth |
| USN-8883-1 | Go (golang-1.18/1.21/1.24) | idna Punycode handling bypasses hostname access controls | CVE-2026-39821 | Ubuntu 22.04 LTS | Update golang |
| USN-8884-1 | U-Boot | ZFS/ext4/IP defrag handling, code exec or DoS | CVE-2025-70290, CVE-2025-70293, CVE-2026-15390, CVE-2026-71971 | 6 LTS releases (16.04 through 26.04) | Update u-boot-tools |
| USN-8892-1 | wsl-pro-service (Ubuntu Pro for WSL) | Attach token exposed in command-line arguments | CVE-2026-102371 | 4 LTS releases (20.04 through 26.04) | Update wsl-pro-service |
| USN-8890-1 | libsoup2.4 / libsoup3 | 8 CVEs: HTTP/2, proxy auth, Range headers, chunked parsing | CVE-2026-4271, CVE-2026-5119, CVE-2026-6324, CVE-2026-66339, CVE-2026-77014, CVE-2026-77680, CVE-2026-85197, CVE-2026-85534 | 6 LTS releases (16.04 through 26.04) | Update libsoup |
| USN-8893-1 | libwebsockets | HTTP/2 HPACK + CBOR/LECP buffer overflows, code exec | CVE-2026-19773, CVE-2026-78161 | 6 LTS releases (16.04 through 26.04) | Update libwebsockets |
| USN-8866-1 | Redis | TLS pending-data memory management; cluster bus packets | CVE-2026-81934, CVE-2026-92925 | 3 LTS releases (22.04 through 26.04) | Update redis |
| USN-8863-1 | GStreamer Good Plugins | FLAC, AVI, closed caption parsing, info disclosure or DoS | CVE-2026-17072, CVE-2026-73433, CVE-2026-73434, CVE-2026-88914 | 6 LTS releases (16.04 through 26.04) | Update gstreamer1.0-plugins-good |
How to apply these Linux security updates
Before running any update commands, check which services are currently active on your system. If Nginx or Apache is handling live traffic, schedule a brief maintenance window or use rolling restarts to minimize downtime during the patching process. Desktop users can usually apply these fixes by opening a terminal and running the standard package manager command for their distribution followed by an upgrade flag. A reboot will be necessary if the kernel received updates to ensure the new security modules load correctly.
Power users who rely on command-line tools like jq should verify the patch level after installation. Regression bugs can occasionally break scripts that depend on specific JSON parsing behavior, so a quick test run is worth the few minutes it takes. If you use PackageKit or other GUI package managers and prefer to skip them because they sometimes hang or try to install junk, do not let that stop you from running the command-line equivalent to get these critical patches applied.
Applying these patches requires distribution-specific package management commands. RHEL-based systems typically use dnf update or yum update, while Debian and Ubuntu rely on apt upgrade. SUSE users should run zypper patch to properly address all security advisories, and Slackware administrators can manage updates with upgradepkg or slackpkg. After executing the commands, a reboot is usually necessary for kernel changes to take effect. Finally, review your package manager’s logs to verify that all patches installed successfully and no dependencies were disrupted.
Debian/Ubuntu (apt)
The first thing to do is refresh the local package index; running sudo apt update contacts all configured repositories and pulls in the newest lists of available versions. Skipping this step leaves the system blind to any recent uploads, which explains why “upgrade” sometimes claims there’s nothing to do even after a security advisory has been published. Once the index is current, invoke sudo apt upgrade -y; the -y flag answers every prompt automatically so the process doesn’t pause for user input. This command upgrades all installed packages that have newer versions in the repositories while preserving configuration files.
sudo apt update sudo apt upgrade -y
Fedora/RedHat/Rocky/Alma/Oracle (dnf or yum)
On modern Fedora and recent Red Hat derivatives, dnf is the package manager; older RHEL releases still rely on yum. Begin with a check‑update operation—sudo dnf check-update or sudo yum check-update—to see exactly which packages are awaiting an upgrade. This preview step can be useful for spotting unexpected kernel bumps before they land. To actually apply the updates, run sudo dnf upgrade -y (or sudo yum update if you prefer the older tool). The upgrade command pulls down the new binaries and runs any necessary post‑install scripts, such as rebuilding initramfs when a kernel changes.
sudo dnf check-update sudo dnf upgrade -y
or on older releases
sudo yum check-update sudo yum update
SUSE (zypper)
SUSE’s command line front‑end is called zypper. First execute sudo zypper refresh so that the metadata for all enabled repos gets updated; without this, zypper will happily report “No updates available” even though newer packages sit on the mirror. After a fresh refresh, issue sudo zypper update -y; this upgrades every package to the latest version in the configured repositories and automatically handles service restarts when required.
sudo zypper refresh sudo zypper update -y
Slackware (slackpkg and pkgtool)
Slackware doesn’t have a single unified updater, but the official way to pull updates is through slackpkg. Start with sudo slackpkg update to download the newest package list from the chosen mirror. Then run sudo slackpkg upgrade-all; this command walks through each installed package and replaces it with the most recent build available in the official repository. For users who prefer a more granular approach, specifying a package name after upgrade limits the operation to that single item. When dealing with community‑maintained repositories, pkgtool takes over: a combined sudo pkgtool update && sudo pkgtool upgrade will sync and apply updates from the mirrors listed in /etc/slackpkg/mirrors.
sudo slackpkg update sudo slackpkg upgrade-all
